cbcvebase.
CVE-2023-30851
published 2023-05-25

CVE-2023-30851: Cilium is a networking, observability, and security solution with an eBPF-based dataplane. This issue only impacts users who have a HTTP policy that applies to…

PriorityP431medium5.3CVSS 3.1
AVNACHPRLUINSUCHINAN
EPSS
0.66%
49.9th percentile
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. This issue only impacts users who have a HTTP policy that applies to multiple `toEndpoints` AND have an allow-all rule in place that affects only one of those endpoints. In such cases, a wildcard rule will be appended to the set of HTTP rules, which could cause bypass of HTTP policies. This issue has been patched in Cilium 1.11.16, 1.12.9, and 1.13.2.

Affected

8 ranges
VendorProductVersion rangeFixed in
ciliumcilium< 1.11.161.11.16
ciliumcilium——
ciliumcilium——
ciliumcilium>= 1.12.0 < 1.12.91.12.9
ciliumcilium>= 1.13.0 < 1.13.21.13.2
github.comcilium_cilium>= 0 < 1.11.161.11.16
github.comcilium_cilium>= 1.12.0 < 1.12.91.12.9
github.comcilium_cilium>= 1.13.0 < 1.13.21.13.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.